SubscribeBTCSCAMWallet Test
Front page / Blind-signing attack · DeFi
highBlind-signing attack · DeFi

Radiant Capital's signers approved a $50 million theft they couldn't see

Malware showed developers one transaction on screen while their hardware wallets signed another. Mandiant ties the October 2024 DeFi heist to North Korea; the protocol later wound down.

MO
Mara Okafor
Chief Investigations Editor · OCT 16, 2024 · 5 min read
Painting: Renaissance archive · Source: CoinDesk

Radiant Capital, a cross-chain DeFi lending protocol, lost an estimated $50 million on Oct. 16, 2024, to an attack that turned its own safeguards against it. The thieves did not guess a password or break a contract's math — they got honest signers to approve transactions none of them could actually see, per CoinDesk.

Radiant guarded major actions with a 3-of-11 multisig: three of eleven authorized signers had to approve, Halborn noted. That breadth was meant to be resilient. Instead it gave the attacker eleven devices to try to compromise.

The screen and the signature diverged

Malware planted on signer machines "display[ed] legitimate transaction data in the Gnosis Safe wallet frontend, while malicious transactions were actually sent to the hardware wallets for signature," Halborn wrote. Signers saw a routine action; their wallets signed a hostile one.

Because occasional transaction failures looked normal, the attackers harvested the needed signatures without raising alarm, per Halborn. Reviewers even simulated the transactions on Tenderly — but blind signing meant the tampering went unseen, and the collected approvals were used to seize the pool provider and upgrade Radiant's contracts to a malicious version.

Attribution and aftermath

Cybersecurity firm Mandiant tied the operation to UNC4736, a North Korean group aligned with the Reconnaissance General Bureau, CoinDesk reported; the initial lure was a malicious file sent to a developer through a spoofed contractor contact. Radiant recovered none of the funds and moved to wind down the protocol.

Radiant is the clearest 2024 case of blind signing defeating a strong multisig. The defenses it points to:

  • Clear-sign where possible: use wallets and workflows that decode and show the real call on the signing device.
  • A compromised laptop can lie about what a hardware wallet is signing; treat the host as hostile.
  • More signers is not automatically more safety — each device is another target, and one malware strain can trick them all.
  • Independent verification of the raw payload, on a separate trusted device, is worth more than any on-screen simulation.

The uncomfortable lesson of Radiant is that a diligent, multi-person approval process can still be walked straight past — if every participant is trusting the same corrupted screen.

— Sources: [CoinDesk](https://www.coindesk.com/tech/2024/12/09/radiant-capital-says-north-korean-hackers-behind-50-million-attack-in-october) · [Halborn](https://www.halborn.com/blog/post/explained-the-radiant-capital-hack-october-2024)

The Rug Report
Every scam that mattered this week, each Sunday.

NOT FINANCIAL ADVICE · VERIFY EVERYTHING